Windows Executable Initiating Connections to ngrok Tunnel Domains
Flags Windows network connections to ngrok tunnel subdomains that may indicate tunneling for C2 or staging.
- Product
- windows
- Category
- network_connection
- Author
- Florian Roth (Nextron Systems) (SigmaHQ), DRL 1.1
- Published
- 2022-11-03
- Updated
- 2026-07-31
ATT&CK techniques
C2 → ExfiltrationRecon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
Exfiltration
Impact
What it detects
This rule flags Windows processes that establish network connections to hostnames containing common ngrok tunnel subdomains (for multiple regions). Such connectivity can indicate use of a tunneling service to support attacker infrastructure, including staging or follow-on payload delivery. It relies on network connection telemetry with destination hostname matching the specified ngrok tunnel patterns.
Reporting behind it
Changelog
v2- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: Windows Executable Initiating Connections to ngrok Tunnel Domains
id: d30ed6cc-82df-4a62-a287-b6dc58174a5b
related:
- id: 18249279-932f-45e2-b37a-8925f2597670
type: similar
- id: 1d08ac94-400d-4469-a82f-daee9a908849
type: derived
status: test
description: This rule flags Windows processes that establish network connections to hostnames containing common ngrok tunnel subdomains (for multiple regions). Such connectivity can indicate use of a tunneling service to support attacker infrastructure, including staging or follow-on payload delivery. It relies on network connection telemetry with destination hostname matching the specified ngrok tunnel patterns.
references:
- https://twitter.com/hakluke/status/1587733971814977537/photo/1
- https://ngrok.com/docs/secure-tunnels/tunnels/ssh-reverse-tunnel-agent
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/network_connection/net_connection_win_domain_ngrok_tunnel.yml
author: Florian Roth (Nextron Systems), Huntrule Team
date: 2022-11-03
modified: 2024-02-02
tags:
- attack.exfiltration
- attack.command-and-control
- attack.t1567
- attack.t1568.002
- attack.t1572
- attack.t1090
- attack.t1102
- attack.s0508
logsource:
category: network_connection
product: windows
detection:
selection:
DestinationHostname|contains:
- tunnel.us.ngrok.com
- tunnel.eu.ngrok.com
- tunnel.ap.ngrok.com
- tunnel.au.ngrok.com
- tunnel.sa.ngrok.com
- tunnel.jp.ngrok.com
- tunnel.in.ngrok.com
condition: selection
falsepositives:
- Legitimate use of the ngrok service.
level: high
license: DRL-1.1